Skip to content

Science1 publisher3 min readPublished

Microsoft's AI bug finders have outrun its Exchange engineers, and CU1 is the casualty

Microsoft has delayed the first cumulative update for Exchange Server Subscription Edition a second time, with no new date, while engineers validate a growing pile of AI-found security findings.

The Scientist · Science desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Microsoft's AI bug finders have outrun its Exchange engineers, and CU1 is the casualty
Generated illustration

What happened

  • In response to customer questions, Microsoft said in a blog post that it was again being forced to delay the first Cumulative Update (CU1) for Exchange Server Subscription Edition because its engineers were racing against time to validate a growing volume of security findings surfaced through AI-assisted code scanning.
  • Microsoft wrote that over the last few months various Microsoft executives made statements explaining how the company is using a variety of AI tools to help find vulnerabilities in its products.
  • Microsoft wrote: "Many teams, Exchange Server included, are working through reported issues - which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly".
  • Microsoft had initially indicated CU1 would arrive by the end of the first half of 2026, before revising the target to the second half of 2026; the latest delay comes with no timeline offered, marking the second time the release window has been pushed back.
  • A Cumulative Update is a periodically released package for Exchange Server that consolidates recent bug fixes and security updates, while also potentially introducing new features, architectural changes or removing deprecated components.

Compiled by The ScientistSomething wrong?How this is made

Why it matters

Microsoft has again delayed the first cumulative update (CU1) for Exchange Server Subscription Edition, telling customers in a blog post that its engineers are racing to validate a growing volume of security findings surfaced through AI-assisted code scanning [1]. It is the second revision to the release window, and this time the company offered no timeline at all [4].

The framing is worth noting because it runs against the standard pitch. AI assistants are generally supposed to compress software development lifecycles; for the Exchange team it may be doing the opposite, leaving enterprise IT waiting on an update that will need extensive compatibility testing once it lands [13].

The mechanics explain why. Microsoft said several of its executives have described the company using a range of AI tools to find vulnerabilities in its products [2], and that "many teams, Exchange Server included, are working through reported issues - which includes validation that they are real security issues, reproducing, fixing, testing for regressions / issues after fixes are deployed and releasing updates monthly" [3]. That is five human steps behind one automated one. The scanner scales; the triage queue behind it does not.

On timing, CU1 was first indicated for the end of the first half of 2026, then moved to the second half, and is now unscheduled [4]. That is a slip of at least six months, followed by the removal of any bound [1].

The distinction between update types is what determines the operational damage. A cumulative update consolidates recent bug fixes and security updates and can also introduce features, make architectural changes, or remove deprecated components [5]. CUs ship once or twice a year, while monthly security updates for Exchange SE have continued consistently [6]. The value of a CU is that administrators can take one consolidated package instead of managing individual updates, but the same breadth means more testing before deployment [7]. Microsoft's own description of its remediation loop ends in monthly releases, the cadence it says it has maintained, so the AI-sourced fixes appear to be landing in the monthly channel while the consolidated package waits [2].

Manoj Chandra Jha, principal analyst at Nord-IQ Research, told Computerworld that the second revision plus the absence of a committed month is reason enough for enterprises to course correct: track the monthly security update cadence as the operational patch baseline, and treat CU1 as a discrete, trigger-based project rather than a scheduled release until Microsoft gives a firmer signal [8]. His preparation list is unglamorous and portable: keep a test environment standing, inventory and pre-validate authentication, APIs and management tools, and set up a fast-track change-approval process that can be activated the day Microsoft announces [9].

Exchange is not an isolated case inside the industry that sells these tools. GitHub, which helped popularise AI-assisted coding through Copilot, has been dealing with the volume and quality of machine-written code [14]; in February it considered letting repository maintainers restrict or disable pull requests after maintainers warned that a surge of low-quality, often AI-generated submissions was overwhelming open-source projects, the core problem being that humans could not review the flood [10]. In April it shipped Stacked PRs to break large changes into smaller reviewable units as AI-assisted development increases the code needing review [11]. AWS added release management features to its DevOps Agent in June for validating, testing and reviewing AI-generated code before deployment [12].

Watch two things. First, whether Microsoft's next Exchange communication names a month or only a trigger condition, since the analyst advice assumes the latter [8]. Second, whether the monthly security update cadence holds while the CU backlog grows [6], because that channel is now the only Exchange patch schedule enterprises can plan against.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories